<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication failed from AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/342058#M85774</link>
    <description>&lt;P&gt;Will need to check your authd.log if you've checked everything from above.&amp;nbsp; I would also double check your firewall policy to ensure that dataplane source interface/zone is allowed to the other zone that 10.10.10.100 exists in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also noticed theres more helpful information in group mapping failures versus auth attempts (lists bad password/fail to connect/etc).&amp;nbsp; Do you have group mapping configured for the associated ldap profile?&amp;nbsp; If you show the group mapping state, what is the output?&lt;/P&gt;&lt;P&gt;CLI&lt;/P&gt;&lt;P&gt;show user group-mapping state &amp;lt;name of group mapping profile referencing the LDAP Profile&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Future troubleshooting for auth specific, if group mapping is successful.&lt;/P&gt;&lt;P&gt;SSH to firewall, issue the following command&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;tail follow yes mp-log authd.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;while that is running, test authentication via another SSH window and paste results (sans business specific information that may be present)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 19:26:43 GMT</pubDate>
    <dc:creator>Chris_Johnston</dc:creator>
    <dc:date>2020-08-04T19:26:43Z</dc:date>
    <item>
      <title>Authentication failed from AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/341833#M85737</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have integrated the AD with Paloalto , it is working fine and i can see the IP user mapping is correct, once i tested authentication profile&lt;/P&gt;&lt;P&gt;I got the below error:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1596457062859.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27114iB0399C155BCF66C3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1596457062859.png" alt="Jafar_Hussain_0-1596457062859.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once i tested the authentication by local profile it is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_1-1596457142802.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27115i750B6A55A1CBF951/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_1-1596457142802.png" alt="Jafar_Hussain_1-1596457142802.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me on this to reolve this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 12:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/341833#M85737</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-03T12:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication failed from AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/341887#M85741</link>
      <description>&lt;P&gt;IP to UserMapping is separate than LDAP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based off your error message in the first screenshot, 'Failed to create a session with LDAP server', I would point towards a network level issue from the firewall MGMT IP (assuming no custom service routing) and the LDAP controller.&amp;nbsp; Could also be permissions on the service account used, but I would bet dollars to donuts it's network level.&amp;nbsp;&lt;SPAN&gt;Also - TLS/389?&amp;nbsp; I know it's possible, but...might need to swap to port 636&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local auth used in second is just authenticating against the local user database on the FW, no LDAP connection needed&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 19:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/341887#M85741</guid>
      <dc:creator>Chris_Johnston</dc:creator>
      <dc:date>2020-08-03T19:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication failed from AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/341913#M85747</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this new setup?&lt;/P&gt;
&lt;P&gt;Please check below document it has step bu step info on troubleshooting&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpoCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpoCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also try below commands to do the TCPdump on the management port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Command to capture LDAP traffic if using management port&lt;/P&gt;
&lt;P&gt;&amp;gt; tcpdump filter "port 389"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Command to view the pcap taken off the management port&lt;/P&gt;
&lt;P&gt;&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 00:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/341913#M85747</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-04T00:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication failed from AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/342057#M85773</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104430"&gt;@Chris_Johnston&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes this is a new setup. i have gone through the documents and changed the service account with ssl/tls 636 port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My LDAP, UID, DNS service route changed via data plane interface&amp;nbsp; I have tried everything but still, the issue is the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 19:05:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/342057#M85773</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-04T19:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication failed from AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/342058#M85774</link>
      <description>&lt;P&gt;Will need to check your authd.log if you've checked everything from above.&amp;nbsp; I would also double check your firewall policy to ensure that dataplane source interface/zone is allowed to the other zone that 10.10.10.100 exists in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also noticed theres more helpful information in group mapping failures versus auth attempts (lists bad password/fail to connect/etc).&amp;nbsp; Do you have group mapping configured for the associated ldap profile?&amp;nbsp; If you show the group mapping state, what is the output?&lt;/P&gt;&lt;P&gt;CLI&lt;/P&gt;&lt;P&gt;show user group-mapping state &amp;lt;name of group mapping profile referencing the LDAP Profile&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Future troubleshooting for auth specific, if group mapping is successful.&lt;/P&gt;&lt;P&gt;SSH to firewall, issue the following command&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;tail follow yes mp-log authd.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;while that is running, test authentication via another SSH window and paste results (sans business specific information that may be present)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 19:26:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failed-from-ad/m-p/342058#M85774</guid>
      <dc:creator>Chris_Johnston</dc:creator>
      <dc:date>2020-08-04T19:26:43Z</dc:date>
    </item>
  </channel>
</rss>

